Decian blog
Threat Advisories
CISA Advisory ICSA-26-204-06: Managing Risk in MZ Automation libIEC61850
CISA has issued advisory ICSA-26-204-06 warning of severe vulnerabilities in the MZ Automation libIEC61850 software library. This library is widely used to support the IEC 61850 standard, which governs communication for power generation, substation automation, and related critical infrastructure. The advisory identifies four distinct flaws that could allow an unauthenticated network-adjacent attacker to disrupt services or take control of a system.
The affected versions of the library range from 1.0.0 up to 1.6.1. The risks here are not theoretical. Two of the identified flaws involve buffer overflows, specifically a stack-based overflow and a heap-based overflow. An attacker could exploit these to execute arbitrary code or cause a denial of service. Another vulnerability allows an attacker to crash a system by sending a malformed message, while a fourth flaw stems from improper handling of invalid data structures.
For mid-market organizations operating in manufacturing, energy, or transportation, the implications are significant. These sectors rely heavily on the visibility and control functions that IEC 61850 facilitates. A crash in a protection system could lead to operational outages or safety risks. The advisory notes that remote code execution is possible, particularly in configurations where Address Space Layout Randomization (ASLR) is disabled. This means the threat is not limited to simple outages but includes the potential for deeper system compromise.
CISA reports that no public exploitation of these specific flaws has been observed yet. However, the absence of active attacks does not eliminate the risk. The vulnerabilities allow for network-adjacent attacks, meaning an attacker does not need internet access to exploit them if they can reach the internal network segment where the device resides. This makes network segmentation and strict access controls even more critical for organizations running these components.
The vendor, MZ Automation, has released updated builds to address these issues. Organizations must prioritize verifying their software versions against the advisory to determine if they are affected. The remediation path involves updating the library to the latest build available through the vendor's GitHub repository. Before applying updates, teams should conduct a risk assessment to understand the operational impact, as restarting affected services may be necessary.
Here are the practical next steps for IT and security teams managing ICS assets:
- Inventory all systems running MZ Automation libIEC61850 to identify affected versions between 1.0.0 and 1.6.1.
- Verify whether your control system devices are exposed to the internet and isolate them behind firewalls immediately.
- Assess your network segmentation to ensure critical manufacturing and energy systems are not accessible from business networks.
- Plan and test the deployment of the latest vendor build to remediate the vulnerabilities.
- Review VPN configurations if remote access is required, ensuring they are updated to the most current secure versions.
- Monitor logs for unusual activity related to MMS requests or GOOSE frames that might indicate probing attempts.
Securing industrial control systems requires vigilance and a structured approach to patch management. At Decian, our SOC and MDR services provide the continuous monitoring and expertise needed to detect threats targeting these critical assets. We help mid-market organizations and their MSP partners navigate these complexities with proactive defense strategies. Visit www.decian.com to learn how we can support your cybersecurity posture.